PT-2022-17007 · Unknown · Eternal Terminal
Adi-Ajit
·
Published
2022-08-16
·
Updated
2024-06-15
·
CVE-2022-24950
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eternal Terminal versions prior to 6.2.0
Description
A race condition exists in the software that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in the
getInfoForId() function of UserTerminalRouter.Recommendations
For versions prior to 6.2.0, update to version 6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
UserTerminalRouter::getInfoForId() function until a patch is available.Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eternal Terminal